Executive brief
The gatsby-source-wordpress plugin leaks HTTP Basic Authentication credentials into the compiled web bundle during build-time, potentially exposing username and password to anyone with access to the generated application files. This exposes sensitive WordPress database credentials that attackers could use to gain unauthorized access to the underlying WordPress instance.
Technical details
The vulnerability is an information disclosure flaw (CWE-200, CWE-522) in gatsby-source-wordpress that fails to filter HTTP Basic Authentication variables from the build-time configuration. When users configure htaccess credentials in gatsby-config.js, the plugin inadvertently bundles these plaintext credentials into the app.js bundle generated at build-time. This occurs client-side during the build process with no user interaction required. An attacker with access to the deployed application files can retrieve the exposed credentials and use them to authenticate directly to the WordPress backend. Patches are available in versions 4.0.8 and 5.9.2, which filter authentication variables from the final bundle.
Affected products
- Gatsby gatsby-source-wordpress <4.0.8; 5.0.0 to <5.9.2
Timeline
- 2021-07-15: disclosed: Advisory published on GitHub
- 2021-07-15: patched: Patches released in versions 4.0.8 and 5.9.2